Impact
SAP Manufacturing Integration and Intelligence (MII) includes a code injection flaw that allows an attacker with high privileges to submit crafted input to specific functions. The input is processed without adequate validation, permitting execution of arbitrary commands on the underlying operating system. This can compromise confidentiality, integrity, and availability of the MII application.
Affected Systems
The vulnerability affects SAP Manufacturing Integration and Intelligence (MII) implementations licensed under the SAP SE product line. Specific affected versions are not enumerated in the data, so the issue applies to all versions of SAP MII that have not yet remediated the input validation oversight.
Risk and Exploitability
The CVSS score of 9.1 signals a critical severity, and the EPSS score is not available, indicating that up‑to‑date exploitation probability is unknown. The flaw is not listed in the CISA KEV catalog. An attacker must have high privileges—typically distributed by SAP users or administrators—to leverage the vulnerability. Once authenticated, the attacker can execute arbitrary system commands, presenting a high risk to confidentiality, integrity, and availability.
OpenCVE Enrichment